Total
20788 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-42564 | 1 Jerryhanjj | 1 Erp | 2026-06-17 | N/A | 7.6 HIGH |
| ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/inventory/delete?action=delete. | |||||
| CVE-2024-42562 | 1 Krishna9772 | 1 Pharmacy Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php. | |||||
| CVE-2024-42561 | 1 Krishna9772 | 1 Pharmacy Management System | 2026-06-17 | N/A | 8.8 HIGH |
| Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php. | |||||
| CVE-2024-42558 | 1 Vaibhavverma9999 | 1 Hotel Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php. | |||||
| CVE-2024-42556 | 1 Vaibhavverma9999 | 1 Hotel Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php. | |||||
| CVE-2024-42554 | 1 Vaibhavverma9999 | 1 Hotel Management System | 2026-06-17 | N/A | 8.8 HIGH |
| Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php. | |||||
| CVE-2024-42552 | 1 Vaibhavverma9999 | 1 Hotel Management System | 2026-06-17 | N/A | 8.6 HIGH |
| Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php. | |||||
| CVE-2024-42533 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attackers to execute arbitrary code via the GEST_LOGIN parameter. | |||||
| CVE-2024-42417 | 1 Deltaww | 1 Diaenergie | 2026-06-17 | N/A | 8.8 HIGH |
| Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product. | |||||
| CVE-2024-42404 | 1 Welcart | 1 Welcart E-commerce | 2026-06-17 | N/A | 8.8 HIGH |
| SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obtain or alter the information stored in the database. | |||||
| CVE-2024-42361 | 1 Apache | 1 Hertzbeat | 2026-06-17 | N/A | 7.5 HIGH |
| Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes a SQL query with user-controlled data, allowing for SQL injection. | |||||
| CVE-2024-42357 | 1 Shopware | 1 Shopware | 2026-06-17 | N/A | 7.3 HIGH |
| Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in the `aggregations` object. The `name` field in this `aggregations` object is vulnerable SQL-injection and can be exploited using SQL parameters. Update to Shopware 6.6.5.1 or 6.5.8.13 to receive a patch. For older versions of 6.1, 6.2, 6.3, and 6.4, corresponding security measures are also available via a plugin. | |||||
| CVE-2024-42327 | 1 Zabbix | 1 Zabbix | 2026-06-17 | N/A | 9.9 CRITICAL |
| A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access. | |||||
| CVE-2024-42005 | 1 Djangoproject | 1 Django | 2026-06-17 | N/A | 7.3 HIGH |
| An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg. | |||||
| CVE-2024-41944 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `report/data/proofofplayReport` API route inside the CMS. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the `sortBy` parameter. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue. | |||||
| CVE-2024-41915 | 1 Arubanetworks | 1 Clearpass Policy Manager | 2026-06-17 | N/A | 7.2 HIGH |
| A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster. | |||||
| CVE-2024-41804 | 1 Xibosignage | 1 Xibo | 2026-06-17 | N/A | 6.5 MEDIUM |
| Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS responsible for Adding/Editing DataSet Column Formulas. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the `formula` parameter. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue. | |||||
| CVE-2024-41803 | 1 Xibosignage | 1 Xibo | 2026-06-17 | N/A | 4.9 MEDIUM |
| Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain arbitrary data from the Xibo database by injecting specially crafted values in to the API for viewing DataSet data. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue. | |||||
| CVE-2024-41802 | 1 Xibosignage | 1 Xibo | 2026-06-17 | N/A | 8.1 HIGH |
| Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the APIs for importing JSON and importing a Layout containing DataSet data. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue | |||||
| CVE-2024-41767 | 3 Ibm, Linux, Microsoft | 3 Engineering Lifecycle Optimization Publishing, Linux Kernel, Windows | 2026-06-17 | N/A | 7.3 HIGH |
| IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |||||
